Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2024-25145Criticalcom.liferay.portal:release.portal.bom: Liferay Portal stored cross-site scripting (XSS) vulnerabilityCVE-2023-39196Mediumorg.apache.ozone:ozone-main: Apache Ozone Improper Authentication vulnerabilityCVE-2023-51437Highorg.apache.pulsar:pulsar-broker-auth-sasl: Apache Pulsar SASL Authentication Provider observable timing discrepancy vulnerabilityCVE-2024-23673Highorg.apache.sling:org.apache.sling.servlets.resolver: Apache Sling Servlets Resolver executes malicious code via path traversalCVE-2023-34042Mediumorg.springframework.security:spring-security-config: Spring Security's spring-security.xsd file is world writableCVE-2024-22567Highnet.mingsoft:ms-mcms: mingSoft MCMS File Upload vulnerabilityCVE-2024-23635Mediumorg.owasp.antisamy:antisamy: Malicious input can provoke XSS when preserving commentsCVE-2024-1143Criticalcom.linecorp.centraldogma:centraldogma-server: Central Dogma Authentication Bypass Vulnerability via Session LeakageCVE-2024-22533Criticalcom.ibeetl:beetl-core: Beetl Server-Side Template Injection vulnerabilityCVE-2024-22236Loworg.springframework.cloud:spring-cloud-contract-shade: Spring Cloud Contract vulnerable to local information disclosureCVE-2024-24565Mediumio.crate:crate: CrateDB database has an arbitrary file read vulnerabilityCVE-2023-51982Highio.crate:crate: CrateDB authentication bypass vulnerabilityCVE-2023-29055Highorg.apache.kylin:kylin-core-common: Apache Kylin has Insufficiently Protected CredentialsCVE-2023-6267Highio.quarkus.resteasy.reactive:resteasy-reactive: Quarkus Improper Handling of Insufficient Permissions or Privileges and Improper Handling of Exceptional Conditions vulnerabilityCVE-2024-23905Highio.jenkins.plugins:redhat-dependency-analytics: Content-Security-Policy disabled by Red Hat Dependency Analytics Jenkins PluginCVE-2024-23902Mediumio.jenkins.plugins:gitlab-branch-source: CSRF vulnerability in Jenkins GitLab Branch Source PluginCVE-2024-23903Lowio.jenkins.plugins:gitlab-branch-source: Non-constant time webhook token comparison in Jenkins GitLab Branch Source Plugin CVE-2024-23904Highorg.jenkins-ci.plugins:log-command: Arbitrary file read vulnerability in Jenkins Log Command PluginCVE-2024-23901Mediumio.jenkins.plugins:gitlab-branch-source: Shared projects are unconditionally discovered by Jenkins GitLab Branch Source PluginCVE-2024-23899Highorg.jenkins-ci.plugins:git-server: Arbitrary file read vulnerability in Git server Plugin can lead to RCECVE-2024-23900Mediumorg.jenkins-ci.plugins:matrix-project: Path traversal vulnerability in Jenkins Matrix Project PluginCVE-2024-23898Highorg.jenkins-ci.main:jenkins-core: Cross-site WebSocket hijacking vulnerability in the Jenkins CLICVE-2024-23897Criticalorg.jenkins-ci.main:jenkins-core: Arbitrary file read vulnerability through the Jenkins CLI can lead to RCECVE-2024-22497Mediumcom.jfinal:jfinal: Cross-site Scripting in JFinalCVE-2024-23636Criticalcom.alipay.sofa:rpc-sofa-boot-starter: Remote Command Execution in SOFARPC

Stop the waste.
Protect your environment with Kodem.